detection-sigma
High Risk 38Build Portable Sigma Detection Rules
SIEM-specific rules are difficult to reuse and maintain across platforms. This skill structures Sigma detections, conversions, ATT&CK mappings, and compliance coverage.
Unified search
Start with the task. Skillstore will show complete packs first, then individual skills when they are a better match.
Showing results for "agent"
Use these when you need one narrow capability instead of a whole pack.
Build Portable Sigma Detection Rules
SIEM-specific rules are difficult to reuse and maintain across platforms. This skill structures Sigma detections, conversions, ATT&CK mappings, and compliance coverage.
Investigate Endpoints with osquery
Endpoint investigations often require many platform-specific tools and commands. This skill provides osquery workflows, detection queries, and packs for consistent forensic collection across major platforms.
Scan Infrastructure Code with Checkov
Infrastructure teams need consistent security checks before deployment. This skill guides Checkov scans, policy customization, suppression governance, compliance mapping, and CI integration.
Investigate Endpoints with Velociraptor VQL
Endpoint investigations require consistent queries, collection plans, and evidence controls. This skill provides Velociraptor workflows, VQL patterns, and deployment templates for authorized response.
Audit Netcat Network Testing Workflows
Network testers need clear netcat workflows for connectivity checks and controlled validation. This skill organizes netcat commands, authorization steps, and documentation guidance.
Audit Metasploit Workflows Safely
Security teams need structured review of authorized exploit validation, but these workflows carry high misuse risk. This skill documents Metasploit assessment steps with scope checks, logging, and cleanup guidance.
Enforce OPA Policy as Code
Security teams need repeatable policy checks across clusters, infrastructure, and compliance controls. This skill guides Claude, Codex, and Claude Code through OPA Rego policy creation, testing, and CI/CD enforcement.
Run Authorized Network Reconnaissance with Nmap
Manual network discovery can miss exposed services and inconsistent configurations. This skill provides structured Nmap workflows for authorized discovery, enumeration, vulnerability checks, and reporting.
Integrate Reviewdog Security Feedback into CI
Security scanner results are often fragmented across CI logs. This skill helps configure reviewdog to publish focused findings in pull requests and local hooks.
Scan Python Code with Bandit
Python security flaws can reach production unnoticed. This skill guides Bandit scans, prioritization, CI integration, and remediation with CWE and OWASP references.
Scan Code with Horusec
Security flaws and exposed secrets can cross language boundaries and reach production. This skill guides Horusec scans, result triage, and CI integration.
Audit Code with Semgrep
Security flaws can remain hidden across large, multilingual repositories. This skill guides focused Semgrep scans, triage, custom rules, CI gates, and standards-aligned remediation.